vulnerability research & proof-of-concept code
screensharingd). Missing error-return in SRP frame-length validation: oversized frames return stale success status, bypassing authentication entirely. Unauthenticated root file read/write via the Apple file-copy protocol → code execution through /etc/sudoers.d/ + /etc/zshenv (SIP-compatible) or crontab injection (SIP disabled). Affects macOS ≤ 26.5 with Screen Sharing enabled.wp2shell pre-auth WordPress RCE chain (CVE-2026-63030 batch desync + CVE-2026-60137 author__not_in SQLi). Anonymous → www-data shell in ~18 requests instead of ~111 by inlining SQL-only bootstrap values as subqueries instead of blind-extracting them bit-by-bit. We did not find this bug. We just got impatient.RRSIG whose Type-Covered field is RRSIG (type 46) survives message parsing, gets cached as a standalone signature, and trips INSIST(related == NULL) in the QP cache — named aborts. All current releases (9.21.x / 9.20 LTS / 9.18 ESV) vulnerable; fix lives on main only. Live trigger endpoint at bind9.sl0p.foo.argv[0] against the allow-list; argv[1..N] pass unfiltered to execvpe(). On cPanel + exim: sandboxed PHP tenant → sendmail -be '${run{cmd}}' → arbitrary command execution outside the namespace sandbox. All OLS versions with namespace sandbox through current (v1.9.1).cronCommand injection + unvalidated phpPath arbitrary file write as root. Write /etc/ld.so.preload → next root fork+exec loads attacker .so → uid=0 in under 5 seconds. Any authenticated user who owns a website. All CyberPanel versions through current.:path pseudo-header splits one HTTP/2 request into two HTTP/1.1 requests on proxied backends. Bypass URL routing, reach unexposed endpoints, desync responses. All OLS reverse-proxy deployments < 1.9.1 affected.